CVE-2020-8191
Citrix application_delivery_controller_firmware Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2020-8191 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 6, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
application_delivery_controller_firmwareBrowse Citrix / application_delivery_controller_firmware | VulnCheck | Version data not supplied | |
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP | CVE List | Citrix ADC and Citrix Gateway 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP 11.1.1a, 11.0.3d and 10.2.7 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMCitrix ADC/Gateway - Cross-Site ScriptingCVSS 6.1
Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 contain a cross-site scripting vulnerability due to improper input validation.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Apply the necessary security patches or updates provided by Citrix to mitigate this vulnerability.
Source: ProjectDiscovery